T09 · Insecure Skill Coding Practices
- Location
start-remote-chrome.sh:307- Finding
Remote desktop services are exposed over plaintext connections and leak credentials in URLs
- Content
View full analysis
/dev/null 2>&1 ``` ```bash if [[ "$NOVNC_LAUNCHER" == *"launch.sh"* ]]; then $NOVNC_LAUNCHER --vnc localhost:${VNC_PORT} --listen ${NOVNC_PORT} >/dev/null 2>&1 & elif [[ "$NOVNC_LAUNCHER" == *"novnc_proxy"* ]]; then $NOVNC_LAUNCHER --vnc localhost:${VNC_PORT} --listen ${NOVNC_PORT} >/dev/null 2>&1 & else # Use websockify $NOVNC_LAUNCHER --web /usr/share/novnc localhost:${NOVNC_PORT} localhost:${VNC_PORT} >/dev/null 2>&1 & fi ``` ```bash echo -e " ${CYAN}${BOLD}http://${HOST_IP}:${NOVNC_PORT}/vnc.html?host=${HOST_IP}&port=${NOVNC_PORT}&password=${VNC_PASSWORD}&autoconnect=true${NC}" echo "" log_info "${BOLD}💻 Or connect via VNC client:${NC}" echo -e " ${CYAN}${BOLD}${HOST_IP}:${VNC_PORT}${NC} ${YELLOW}(Password: ${VNC_PASSWORD})${NC}" echo "" log_info "${BOLD}🔑 VNC Password: ${CYAN}${BOLD}${VNC_PASSWORD}${NC}" ``` The documentation also explicitly recommends opening all relevant ports: ```bash sudo ufw allow 5900/tcp sudo ufw allow 6080/tcp sudo ufw allow 9222/tcp ``` ### Technical Analysis The x11vnc and noVNC commands do not explicitly restrict their listening sockets to the loopback interface. Depending on the tools' defaults, they may listen on all network interfaces. The documentation reinforces broad network exposure by instructing users to open the VNC, noVNC, and Chrome debugging ports in the firewall. The recommended noVNC URL uses plaintext HTTP and includes the VNC password as a query parameter. Query-string credentials can be retained in shell logs, terminal captures, browser history, bookmarks, monitoring systems, screenshots, copie ...[truncated 1270 chars]- Remediation
View remediation
